MAL-2026-13425

    Dashboard / Malicious Package / MAL-2026-13425

    MAL-2026-13425

    Published: 6 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in typst-resume-cli (npm)

    Details: Source: amazon-inspector (104d03639d9a9d48d03641fef83163391bb1540c8a01c56287bcaf8ca45ad01c) index.js loads https, http, and child_process at the top of the module and sends host/environment data to a hardcoded AWS Lambda URL at https://oo7fsr4cy32q42bzkpgwhy7asu0hzaod.lambda-url.us-east-1.on.aws. The code reads process.env and branches on process.platform before issuing an https.request to that endpoint. The destination is an attacker-controlled serverless URL unrelated to a Typst or resume tooling publisher, and the collected data (environment variables and host attributes) is credential-grade content leaving the installer's machine.

    Affected packages

    Package

    Name: typst-resume-cli

    Purl: pkg:npm/typst-resume-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.2
    1.0.3
    MAL-2026-13425 | CVE-DB